Idira Endpoint Privilege Manager by Palo Alto Networks
To find out if this integration is available in your organization, see your Datadog Integrations page or ask your organization administrator.
To initiate an exception request to enable this integration for your organization, email support@ddog-gov.com.
Idira EPM Policy Audit Events
Idira EPM Policy Audit Events
Idira EPM Set & Account Admin Activities
Idira EPM Set & Account Admin Activities
Overview
Idira Endpoint Privilege Manager enforces least privilege and enables organizations to block and contain attacks on endpoint computers, reducing the risk of information being stolen or encrypted and held for ransom.
This integration ingests the following logs:
- Raw Events: Endpoint activities captured by EPM agents, including threat detection events.
- Policy Audit Events: Audit records of policy usage on endpoints.
- Set Admin Audit Events: Actions carried out by EPM administrators within sets.
- Account Admin Audit Events: Actions performed by account administrators.
Integrate Idira Endpoint Privilege Manager with Datadog to gain insights into raw events, policy audit events, set admin audit events, and account admin audit events using pre-built dashboard visualizations. Datadog uses its built-in log pipelines to parse and enrich these logs, facilitating easy search and detailed insights. Additionally, the integration can be used for Cloud SIEM detection rules for enhanced monitoring and security.
Setup
Create a Role and Assign a User in Idira Endpoint Privilege Manager
- Log in to the Idira Endpoint Privilege Manager portal and navigate to Administration.
- Open the Roles section and click Create role.
- Enter the role details:
- Name: Name of the role (e.g., View Only Set Admin Role)
- Permission groups: Select
View Only Set Admin - Sets: Select the required sets to collect data
- Click Create.
- Open the Users section and click Add user.
- Enter the user details:
- User email, Password, and Confirm password
- Click Add.
A verification email is sent to the provided address. The user must open the email and click the verification link to activate the account before proceeding.
- Open the Role assignment section, locate the newly created role, and click Assign or unassign users from its options menu.
- Click Assign users, select the newly created user’s email, click Assign.
- Click Save.
- Locate the Account Admin ViewOnly Role, and click Assign or unassign users from its options menu.
- Click Assign users, select the newly created user’s email, click Assign.
- Click Save.
Connect your Idira Endpoint Privilege Manager Account to Datadog
- Add your
EPM Account Region, Username, and Password.| Parameters | Description |
|---|
| EPM Account Region | The EPM Account Region of your Idira Endpoint Privilege Manager. |
| Username | The Username of Idira Endpoint Privilege Manager account which has access to the available sets. |
| Password | The Idira Endpoint Privilege Manager account password. |
- Click Save.
Data Collected
The Idira Endpoint Privilege Manager integration collects and forwards raw events, policy audit events, set admin audit events, and account admin audit events to Datadog.
Metrics
The Idira Endpoint Privilege Manager integration does not include any metrics.
Events
The Idira Endpoint Privilege Manager integration does not include any events.
Troubleshooting
Need help? Contact Datadog support.